184
2 Computer Viruses, Malicious Logic, and Spyware
example of similar malware that the company had come across in previous years.
An example of such program was first discovered on servers of Belgacom, a Belgian
telecommunication company.
At that time, the Intercept performed its own internal investigation and unambiguously (which is rare) concluded that Reign was specifically used by intelligence
services of the USA and the Great Britain.
Security experts placed Reign on a par with other supposedly state-controlled
Trojans like Stuxnet (mentioned above), Flame, Duqu, and Turla (Snake). In 2014,
28% of confirmed cases of infection were found in Russia; 24% of cases were
registered in Saudi Arabia.
Reign is an extremely aggressive multi-level spy program in which every level is
very well masked and encrypted (except for the first stage). Launch of this program
during the first stage, as planned by the developers, will result in a chain reaction with
decryption of each subsequent stage. All the five levels of the spy program Reign are
shown in Fig. 2.34.
Only after implementation of these five levels, it is possible to analyze the fact
of presence and functionality of this program. This is the reason why no one could
find it for such a long time. According to Symantec experts, the first of the designed
versions of the program was used approximately between 2008 and 2011; the second
period of active attacks happened in 2013.
This spy program (Reign) also has multiple various additional modules with
payload data. For example, the RAT module allows making screenshots, remotely
controlling the mouse, or copying passwords. This module also analyzes Internet
traffic, restores all deleted files, etc. There are also other modules, including the
special module for monitoring the traffic of the Microsoft IIS web server, the base
station controller sniffer, and many other modules: the work was clearly performed
by professional controllers, not by single enthusiasts.
2.7 Example of Injection of a Software
Trojan into a standard PE file of Microsoft Windows OS
2.7.1 Purpose and Structure of PE Files
In the beginning of this section, we are going to try and justify why we have chosen
PE files specifically as an example of the most popular ways of introducing software
Trojans (backdoors).
Portable executable (PE) is a common format of executable files, object code, and
dynamic libraries used in 32-bit and 64-bit versions of Microsoft Windows. PE format
is the data structure containing all information required by a PE loader to reproduce
file in memory. The executable code includes links for binding of dynamically loaded
2 Computer Viruses, Malicious Logic, and Spyware
example of similar malware that the company had come across in previous years.
An example of such program was first discovered on servers of Belgacom, a Belgian
telecommunication company.
At that time, the Intercept performed its own internal investigation and unambiguously (which is rare) concluded that Reign was specifically used by intelligence
services of the USA and the Great Britain.
Security experts placed Reign on a par with other supposedly state-controlled
Trojans like Stuxnet (mentioned above), Flame, Duqu, and Turla (Snake). In 2014,
28% of confirmed cases of infection were found in Russia; 24% of cases were
registered in Saudi Arabia.
Reign is an extremely aggressive multi-level spy program in which every level is
very well masked and encrypted (except for the first stage). Launch of this program
during the first stage, as planned by the developers, will result in a chain reaction with
decryption of each subsequent stage. All the five levels of the spy program Reign are
shown in Fig. 2.34.
Only after implementation of these five levels, it is possible to analyze the fact
of presence and functionality of this program. This is the reason why no one could
find it for such a long time. According to Symantec experts, the first of the designed
versions of the program was used approximately between 2008 and 2011; the second
period of active attacks happened in 2013.
This spy program (Reign) also has multiple various additional modules with
payload data. For example, the RAT module allows making screenshots, remotely
controlling the mouse, or copying passwords. This module also analyzes Internet
traffic, restores all deleted files, etc. There are also other modules, including the
special module for monitoring the traffic of the Microsoft IIS web server, the base
station controller sniffer, and many other modules: the work was clearly performed
by professional controllers, not by single enthusiasts.
2.7 Example of Injection of a Software
Trojan into a standard PE file of Microsoft Windows OS
2.7.1 Purpose and Structure of PE Files
In the beginning of this section, we are going to try and justify why we have chosen
PE files specifically as an example of the most popular ways of introducing software
Trojans (backdoors).
Portable executable (PE) is a common format of executable files, object code, and
dynamic libraries used in 32-bit and 64-bit versions of Microsoft Windows. PE format
is the data structure containing all information required by a PE loader to reproduce
file in memory. The executable code includes links for binding of dynamically loaded
